The package is licensed, documented, tested in the repository, and the latest release includes release notes. Its sparse release history, quiet recent commit activity, and limited workflow hardening leave less evidence of sustained support.
66%
Total Score
50
90
50
The package has only 4 releases over about 3 years, with one release in the last 12 months and a median interval of about 363 days. The recent v1.3.0 release is positive, but the overall cadence provides limited evidence of sustained maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. A recent release and push show current activity, but the short-term silence still weakens confidence in ongoing support.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a transparency gap, not evidence that the package is unsafe.
All 11 analyzed action references are unpinned, and 2 workflows grant top-level write permissions. No untrusted checkout, script injection, or high-confidence audit findings were reported, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.